Fortinet FortiWeb SQL Injection Vulnerability Allowing Information Disclosure

Vulnerability

A SQL injection vulnerability has been identified in Fortinet FortiWeb versions 6.3.17 through 7.6.1. This vulnerability arises from improper neutralization of special elements used in SQL commands, allowing attackers to execute crafted SQL queries that could lead to unauthorized information disclosure.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information through crafted SQL queries.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.